Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,089
Mitigations
Mitigation rules
17,016
No official patch
13,354
In triage
1,233
Published soon
0
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
yayson
<= 4.2.0
NPM: yayson: Prototype pollution in Store/LegacyStore deserialization
9.1
2 days ago
@mockoon/commons-server
< 9.7.0
NPM: @Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
8.8
2 days ago
@mockoon/cli
< 9.7.0
NPM: @Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
8.8
2 days ago
@mockoon/commons-server
<= 9.6.1
NPM: @Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
6.5
2 days ago
@mockoon/cli
<= 9.6.1
NPM: @Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
6.5
2 days ago
mcp-from-openapi
>= 2.3.0, < 2.5.0
NPM: FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
8.5
2 days ago
@frontmcp/adapters
>= 1.2.1, < 1.5.0
NPM: FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
8.5
2 days ago
frontmcp
>= 1.2.1, < 1.5.0
NPM: FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
8.5
2 days ago
The Events Calendar
<= 6.17.4
Unauthenticated PHP Object Injection to Remote Code Execution vulnerability
9.8
2 days ago
The Events Calendar
<= 6.17.3
Unauthenticated Code Injection to Remote Code Execution vulnerability
9.8
2 days ago
GEO my WordPress
<= 4.5.5.3
Unauthenticated Local File Inclusion vulnerability
7.5
2 days ago
MPG
<= 4.2.1
Unauthenticated SQL Injection vulnerability
9.3
2 days ago
Tutor LMS
<= 4.0.7
Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution vulnerability
8.8
2 days ago
bbPress
<= 2.6.14
Sensitive Data Exposure vulnerability
5.3
2 days ago
DT LMS – elearning, WordPress LMS Plugin
<= 1.1
Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification vulnerability
5.3
2 days ago
ElasticPress
<= 5.3.4
Sensitive Data Exposure vulnerability
5.3
2 days ago
Master Addons for Elementor
<= 3.2.2
Broken Access Control vulnerability
7.1
2 days ago
WP-Members
<= 3.5.6
Reflected Cross-Site Scripting vulnerability
7.1
2 days ago
Registration Form for WooCommerce
1.1.0-1.1.2
Contributor+ Privilege Escalation vulnerability
8.8
2 days ago
Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons
< 3.3.3
Unauthenticated Stored XSS vulnerability
7.1
2 days ago
Load more